logo

Laravel Passport Patches Machine-to-Human Authentication Bypass

ID: 9734a8ac-2b82-5fdc-9e30-1ebbc73c30ac

STIX ID: report--9734a8ac-2b82-5fdc-9e30-1ebbc73c30ac

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-13

Date Updated: 2026-04-23

Author: Ddos

...
...

Laravel Passport CVE-2026-39976 (CVSS 7.1) details an authentication bypass in TokenGuard where client_credentials tokens may be resolved to actual user accounts if client and user IDs collide (notably when Passport::$clientUuids is disabled). The issue can let machine-to-machine tokens act with user privileges; upgrade to v13.7.1+ or disallow the client_credentials grant as interim mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.